Restricted Use Report
A restricted use report is an auditor's report whose distribution and use are limited to specific parties named or identified in the report, rather than being available to the general public. It alerts readers that the report is not intended for anyone outside those specified users, because it addresses matters relevant only to those parties. SOC 2 Type I and Type II reports are typically issued as restricted use reports intended for the service organization, its user entities, and other knowledgeable parties.
A restricted use report is an attestation or audit report in which the practitioner adds language limiting the intended use to identified parties, indicating that the report is not intended to be, and should not be, used by anyone other than those specified users. Restriction is applied when the subject matter or criteria are suitable only for parties who understand them, or when the report addresses matters relevant to particular users. SOC 2 examinations performed under the AICPA's attestation standards (SSAE 18) generally result in restricted use reports intended for the service organization's management, user entities, and parties with sufficient knowledge of the system and controls; this distinguishes them from SOC 3 reports, which are general use. The historical guidance on restricting report use in AU Section 532 has been superseded in the AICPA clarified standards, and the concept of restricted use remains embedded in current attestation reporting practice. The restriction affects distribution only and does not narrow the scope of the controls or period covered by the underlying examination.
Why it matters
The restricted use designation on a SOC 2 report is a defining feature of how these examinations are shared and consumed. Because SOC 2 Type I and Type II reports are typically issued as restricted use reports, they are intended only for the service organization, its user entities, and other parties with sufficient knowledge of the system and controls to interpret them correctly. This matters because the detailed contents of a SOC 2 report, including descriptions of controls, test procedures, and results, are meaningful only to readers who understand the system context. Distributing such a report to the general public or to parties without that context risks misinterpretation of what the report does and does not convey.
For compliance managers and auditors, understanding the restriction is essential to managing report distribution appropriately. A restricted use report cannot serve the marketing or public-assurance function that a general use report provides; that is the role of a SOC 3 report, which is designed for general distribution. Confusing the two, or sharing a restricted use SOC 2 report beyond its intended audience, can create both practical and professional complications. The restriction is a statement about intended audience, not a limitation on the rigor of the underlying examination.
It is important to remember that the restriction affects distribution only and does not narrow the scope of the controls or the period covered by the underlying examination. A SOC 2 report attests solely to the controls and period it covers and does not guarantee freedom from breaches; the restricted use language governs who may rely on the report, not the assurance the examination provides.
Who it's relevant to
Inside Restricted Use Report
Common questions
Answers to the questions practitioners most commonly ask about Restricted Use Report.